<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Stops sending OSPF hellos in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628117#M422503</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sundar,&lt;/P&gt;&lt;P&gt;Many thanks for your assistance, this looks very similar to the problem that happened. I think I found out the root cause of the problem, the DC were changing the power to a metered power system that weekend, and seems the ASAs were booted before the 3750 stack, hence the arp cache corruption.&lt;/P&gt;&lt;P&gt;Currently with the ASAs working, I have the following Mac addresses, which one would you suggest needs to have a static entry;&lt;/P&gt;&lt;P&gt;Inside 192.168.16.3 0018.7317.93fb (the failover asa)&lt;/P&gt;&lt;P&gt;Inside 224.0.0.5 0100.5e00.0005&lt;/P&gt;&lt;P&gt;Inside 192.168.16.1 0019.2f70.8044 (3750 stack).&lt;/P&gt;&lt;P&gt;Inside MAC address 0018.1900.3a3f (the active asa inside address).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need a static arp on the 3750 stack as well, this was sending hellos ok during the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your expert advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, Adrian.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Feb 2007 09:24:11 GMT</pubDate>
    <dc:creator>aoshea</dc:creator>
    <dc:date>2007-02-26T09:24:11Z</dc:date>
    <item>
      <title>ASA Stops sending OSPF hellos</title>
      <link>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628113#M422499</link>
      <description>&lt;P&gt;ASA Stops sending OSPF hellos&lt;/P&gt;&lt;P&gt;Dear Support,&lt;/P&gt;&lt;P&gt;Wondering if anyone else has come across this problem, but have two Cisco ASA 5510s ASA V7.2(1), DM V5.2(1) (in active/passive failover configuration). These are connected to a pair of 3750G-48-EMIs in a stack, OSPF is running on both, The ASAs are redistributing the outside, and DMZ interfaces by a defined route-map.&lt;/P&gt;&lt;P&gt;Everything normally works fine, but today I found that the neighbour relationship between the ASAs and 3750s had broke. I tried clearing the OSPF process on both the ASAs and 3750, but this would not resolve the problem. The 3750 would not show the ASAs in the neighbour list, but did have other devices (via a point-to-point link) as FULL state. The ASAs however would show the 3750s as INIT/DROTHER state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debugs showed that the ASAs were receiving hellos from the 3750s but was not sending any. The 3750s showed it was sending hellos but not receiving any from the ASAs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To resolve I had to reboot the ASAs. This is not my preferred solution as should not need to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else come across this problem, and is there a resolution? Or a bug track id?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance for your assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I always rate helpful replies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, Adrian&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628113#M422499</guid>
      <dc:creator>aoshea</dc:creator>
      <dc:date>2020-02-21T09:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stops sending OSPF hellos</title>
      <link>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628114#M422500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello adrian&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How frequent does this happen ?? I saw a bug ID CSCsd97134 - PIX/ASA ignores OSPF DBDs during adajency building , but this has been resolved in 7.2(1) , as per the release notes... might be some other issue.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the ASA in active-standby or active-active mode ? with active/active routing protocols will have issues... can you post us the configs if possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2007 00:27:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628114#M422500</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2007-02-23T00:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stops sending OSPF hellos</title>
      <link>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628115#M422501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your symptoms seem to indicate you may be affected by this bug. If you are running one of the affected codes then apply the workaround suggested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCsg00914 Bug Details  	&lt;/P&gt;&lt;P&gt;		&lt;/P&gt;&lt;P&gt;Headline 	 OSPF neighbors dont form due to corrupted arp entry&lt;/P&gt;&lt;P&gt;Product 	 pix-asa&lt;/P&gt;&lt;P&gt;Feature 	 Unicast Routing    Components 	Duplicate of 	 &lt;/P&gt;&lt;P&gt;Severity 	 3  Severity help 	Status 	 Verified  Status help&lt;/P&gt;&lt;P&gt;First Found-in Version 	 7.2(1), 7.0(6) 	First Fixed-in Version 	 7.2(2), 7.2(1.26), 7.1(2.30), 7.0(6.10), 8.0(0.111)  Version help&lt;/P&gt;&lt;P&gt;Release Notes&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Symptom:&lt;/P&gt;&lt;P&gt;OSPF neighbors don't form&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conditions:&lt;/P&gt;&lt;P&gt;show ospf neighbors on the ASA running&lt;/P&gt;&lt;P&gt;7.2.1 displays the neighbors in INIT/DROTHER state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA may be attempting to send OSPF packets to a MAC address other than the&lt;/P&gt;&lt;P&gt;intended one, though non broadcast is disabled on the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround:&lt;/P&gt;&lt;P&gt;Clear the arp cache on the asa. If clearing the arp does not work, try adding a&lt;/P&gt;&lt;P&gt;static arp entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further Problem Description:&lt;/P&gt;&lt;P&gt;A show arp should list the multicast address on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sundar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2007 00:43:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628115#M422501</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2007-02-23T00:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stops sending OSPF hellos</title>
      <link>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628116#M422502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello sundar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You hit the nail right on the head !!! surprising to see this through bug tool kit, but not included on the release notes of 7.2(1) !!!! I thought the release notes were the most authentic info ever that I will get  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2007 00:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628116#M422502</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2007-02-23T00:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stops sending OSPF hellos</title>
      <link>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628117#M422503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sundar,&lt;/P&gt;&lt;P&gt;Many thanks for your assistance, this looks very similar to the problem that happened. I think I found out the root cause of the problem, the DC were changing the power to a metered power system that weekend, and seems the ASAs were booted before the 3750 stack, hence the arp cache corruption.&lt;/P&gt;&lt;P&gt;Currently with the ASAs working, I have the following Mac addresses, which one would you suggest needs to have a static entry;&lt;/P&gt;&lt;P&gt;Inside 192.168.16.3 0018.7317.93fb (the failover asa)&lt;/P&gt;&lt;P&gt;Inside 224.0.0.5 0100.5e00.0005&lt;/P&gt;&lt;P&gt;Inside 192.168.16.1 0019.2f70.8044 (3750 stack).&lt;/P&gt;&lt;P&gt;Inside MAC address 0018.1900.3a3f (the active asa inside address).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need a static arp on the 3750 stack as well, this was sending hellos ok during the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your expert advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, Adrian.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2007 09:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628117#M422503</guid>
      <dc:creator>aoshea</dc:creator>
      <dc:date>2007-02-26T09:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Stops sending OSPF hellos</title>
      <link>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628118#M422504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adrian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bug workaround suggests adding static ARP for the neighbor device. Add a static ARP entry for the 3750 on your ASA. The bug only applies to ASA and hence, you shouldn't need a static entry on the 3750.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sundar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2007 21:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-stops-sending-ospf-hellos/m-p/628118#M422504</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2007-02-26T21:39:49Z</dc:date>
    </item>
  </channel>
</rss>

